APT-level red team operations for enterprises and organizations

What an operation actually looks like

Real patterns from real engagements, anonymized and sanitized: names, sectors and infrastructure details changed — the tradecraft, timelines and lessons intact. Open any case file for the full path, the detection gap and the fixes.

RT-0142 Financial sector

From a job posting to Domain Admin in six days

A developer's home NAS, a reused local-admin password across 60+ hosts — and push #14 that someone finally approved.

Open case file
RT-0117 SaaS provider

The crown jewels were one consent prompt away

No exploit at all: a policy lure, two approved MFA prompts and one standing OAuth grant with Graph scope over mailboxes.

Open case file
RT-0098 Energy / OT adjacent

A clean IT/OT boundary — until the vendor laptop

The segmented OT network held. The dual-homed maintenance laptop that legitimately bridged the zones did not.

Open case file
RT-0171 Telecom

Six hours from a helpdesk call to global admin

Pure vishing: a confident voice, a conference speaker list and a re-enrollment queue that auto-elevated into a tier-0 role.

Open case file
RT-0203 Manufacturing site

The €40 badge that opened the production wing

A low-frequency RFID badge cloned at a distance of half a meter — and a secure corridor where nobody checked faces.

Open case file
RT-0226 Retail / e-commerce

A public bucket nobody owned

A forgotten data-lake bucket, open to the internet since a migration three years ago — no exploit, no credentials, no alerts.

Open case file
RT-0247 Call-center

We stopped a 300,000-customer data breach overnight

A SQL injection, cracked admin hashes — and a daily root task holding a backdoor open in production.

Open case file
RT-0268 CRM vendor

From a leak in a bot to root on 22 servers

A working account from a breach dump, an IDOR, a web shell — and an Ansible key granting root on 22 servers.

Open case file
RT-0291 Vulnerability research

Our 0-day: a WordPress plugin that hands out admin

Import Users from CSV ≤ 1.3.1: the create_users capability turned into a full administrator. CVSS 7.2.

Open case file

Every case above ended with fixes that held on retest. The same patterns appear across industries — the question is not whether they apply to you, but which one is already open. Ask us which.

What would our next case file say about you?

Every engagement above ended with fixes that held. Start yours before an attacker writes it for you.

Request assessment